New:Introducing Socket Scanning for VS Code Marketplace Extensions.Learn more →
Get Started

@haimkastner/workforce-ai-mcp

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@haimkastner/workforce-ai-mcp

MCP server for Workforce AI — policy management, asset visibility, and apps catalog via LLM tool calls

latest
npmnpm
Version
1.0.0-rc.4
Version published
Maintainers
1
Created
Source

Check Point - Workforce AI MCP Server

License npm version

Pre-release disclaimer: This package is currently in release candidate (RC) stage and is intended for testing and evaluation purposes only. APIs and tool definitions may change before the stable release. Do not use in production environments.

An MCP (Model Context Protocol) server that exposes Check Point Workforce AI capabilities as LLM tools — enabling AI assistants to query, analyze, and manage AI & Browse security policies, assets, and applications through natural language.

Getting started

Obtaining API credentials

  • Go to the Infinity Portal API Keys page.
  • Click New > New Account API Key.
  • In the Service dropdown select Workforce AI Security (and for Browse, Browse Security) and create the key.
  • Copy the Client ID, Secret Key, and Authentication URL (gateway).

For more information, see Infinity Portal Administration Guide.

Available gateways

RegionGateway URL
Europehttps://cloudinfra-gw.portal.checkpoint.com
United Stateshttps://cloudinfra-gw-us.portal.checkpoint.com

Environment variables

VariableRequiredDescription
CP_CI_CLIENT_IDYesCloudInfra API key client ID
CP_CI_ACCESS_KEYYesCloudInfra API key secret
CP_CI_GATEWAYYesCloudInfra gateway URL
MCP_MODEYesTransport mode: stdio or http
PORTWhen httpHTTP server port
WRITE_MODENoSet to true to enable write tools (default: false).
Warning: enabling write mode allows the LLM to create, modify, and delete security policy rules. Use with caution.

Running with stdio transport

Use stdio mode when connecting directly from an MCP client such as Claude Desktop, VS Code, or Cursor:

CP_CI_CLIENT_ID="your-client-id" \
CP_CI_ACCESS_KEY="your-access-key" \
CP_CI_GATEWAY="https://cloudinfra-gw-us.portal.checkpoint.com" \
MCP_MODE=stdio \
npx @haimkastner/workforce-ai-mcp

Claude Desktop configuration

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "workforce-ai": {
      "command": "npx",
      "args": ["--yes", "@haimkastner/workforce-ai-mcp"],
      "env": {
        "CP_CI_CLIENT_ID": "your-client-id",
        "CP_CI_ACCESS_KEY": "your-access-key",
        "CP_CI_GATEWAY": "https://cloudinfra-gw-us.portal.checkpoint.com",
        "MCP_MODE": "stdio"
      }
    }
  }
}

Running with HTTP transport

Use HTTP mode when running the server as a standalone service:

CP_CI_CLIENT_ID="your-client-id" \
CP_CI_ACCESS_KEY="your-access-key" \
CP_CI_GATEWAY="https://cloudinfra-gw-us.portal.checkpoint.com" \
MCP_MODE=http \
PORT=3000 \
npx @haimkastner/workforce-ai-mcp

The server exposes:

  • POST /mcp — MCP StreamableHTTP endpoint
  • GET /health — Health check

Capabilities

Read mode (default)

By default, the server starts in read-only mode, exposing tools for querying and analyzing policies without making any changes. This is safe for exploration and auditing.

Policy inspection

  • List rulebases — View all rules for Chats (GenAI DLP), AI Access, Web Access, Agents, Secure Browsing, and DLP policies
  • Analyze shadow rules — Detect rules that are shadowed (never matched) by higher-priority rules
  • Simulate policy matching — Given a user and target, resolve which rule in the rulebase would apply

Assets and users

  • Search assets — Find managed assets by name or attributes
  • Count assets — Get asset counts with optional filters
  • Search users — Look up users and groups in the organization

Applications and data types

  • Search apps — Search the GenAI application catalog by name, description, or URL
  • Get apps by ID — Retrieve application details by their IDs
  • List DLP data types — Browse predefined and custom DLP data types
  • Get tenant DLP data types — View data types configured for the tenant

Policy objects

  • List domain objects — View domain-based policy objects
  • List file protection objects — View file protection configurations

Write mode

To enable write operations, set WRITE_MODE=true. This unlocks tools that modify the policy configuration:

Rule management

  • Create rules — Create new Chats, AI Access, Agents, DLP, and Secure Browsing rules with full policy configuration including actions, services, data types, and user/group assignments
  • Edit rules — Update rule name, description, and other properties
  • Activate / deactivate rules — Toggle rules on or off
  • Reorder rules — Change rule priority in the rulebase
  • Delete rules — Permanently remove rules from the rulebase

Available tools

ToolDescriptionMode
list_chats_rulesList all Chats (GenAI DLP) rules.read
list_ai_access_rulesList all AI Access rules that control which AI services and applications users are allowed to interact with.read
list_web_access_rulesList all Web Access rules for Browse Security.read
list_agents_rulesList all Agents (MCP Server) rules that govern agent interactions.read
list_secure_browsing_rulesList all Secure Browsing threat-prevention rules.read
list_dlp_rulesList all Browse DLP (Data Loss Prevention) rules for browser security.read
set_rule_infoUpdate the display name and description of a rule identified by its UUID.write
set_rule_activeEnable or disable a rule without deleting it.write
reorder_ruleMove a rule to a new position in the rulebase.write
delete_rulePermanently delete a rule from the rulebase by its UUID.write
create_chats_ruleCreate a new Chats (GenAI DLP) rule.write
create_ai_access_ruleCreate a new AI Access rule that controls which AI services and applications users can interact with.write
create_agents_ruleCreate a new Agents (MCP Server) rule that governs agent interactions.write
create_dlp_ruleCreate a new Browse DLP rule for data loss prevention during web browsing.write
create_secure_browsing_ruleCreate a new Secure Browsing threat-prevention rule.write
list_file_protection_objectsList all file-protection policy objects.read
list_domains_objectsList all domains policy objects.read
get_tenant_dlp_datatypesGet the tenant-specific DLP datatype configuration showing which data types are currently enabled for detection in this tenant's policies..read
search_dlp_datatypesSearch DLP data types by name or description with pagination.read
analyze_shadow_rulesFind unreachable (shadowed) rules in a rulebase.read
resolve_matching_ruleGiven a user and target, determine which rule in the rulebase would apply.read
search_assetsSearch deployed assets (endpoints/devices) with optional filtering, sorting, text search, and pagination.read
count_assetsGet the total count of deployed assets, optionally filtered.read
search_usersSearch users in the organization with optional text search and pagination.read
search_appsSearch the GenAI apps catalog by name, description, or URL.read
get_apps_by_idsGet specific GenAI apps from the catalog by their numeric IDs.read

Report Bug

In case of an issue or a bug found in the MCP server, please open an issue.

Contributors

Keywords

mcp

FAQs

Package last updated on 06 Apr 2026

Related posts